25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Ohio MHAS Exposes PHI of 59K Patients by Mailing Surveys on Postcards

This week, patients of the Ohio Department of Mental Health and Addiction Services (OMHAS) were notified of a privacy incident that occurred on February 3, 2016.

Patients were sent a satisfaction survey by mail; however, the survey request was sent on postcards rather than in sealed envelopes. Consequently, the fact that each patient had received services related to mental health and addition was inadvertently exposed along with patients’ names and addresses.

This was not the first time that these mailings were sent to patients. Each year, OMHAS sends customer satisfaction surveys to patients to obtain feedback about the services they received. The aim of the mailings is to obtain data from patients that can be used to improve the services OMHAS provides and as part of the reporting requirements required for the federal Mental Health Block Grant.

On February 25, 2016, OMHAS became aware that the mailing breached Health Insurance Portability and Accountability Act Rules. An investigation into the privacy breach revealed that similar mailings had been sent in the past. In total, 59,000 patients were affected by the privacy incident.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

While no highly sensitive data such as financial information, Insurance details, medical data, or Social Security numbers were exposed as a result of any of the mailings, it is conceivable that patients could come to harm or suffer discrimination by disclosing that they were patients of OMHAS.

OMHAS is now in the process of notifying all affected patients of the privacy breach by mail. The incident has prompted OMHAS to conduct a review of internal policies and procedures relating to customer outreach. In future, all mailings of this nature will be sent in sealed envelopes rather than using postcards to ensure that the privacy of patients is protected. Additional training on privacy will also be provided to all department staff members.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist